The Current Status of the Job Search: ATS Filters, AI Interviews, Fake Offers, and Constant Rejections
A short field report from the 2026 hiring market - what's broken, what's working, and why I'm still looking.
I've been job searching seriously since the layoff. CISSP, six years at a security product company, a decade of building software. Still looking.
This isn't a rant. It's a field report.
The pipeline lie
Everyone describes hiring as a funnel. Reality feels more like shouting into an ATS-shaped void.
Applications go out. Some bounce back in 48 hours - too fast for a human to have read anything meaningful. Some vanish. Some sit in "still reviewing" forever, which translates to "you're in a database with four hundred people who listed ISO 27001."
High volume in. Low signal out.
ATS filters
Applicant Tracking Systems were supposed to organize hiring. Many function as accidental gatekeepers - keyword matchers without context.
I mirror job descriptions, use clean formatting, write tailored cover letters for roles I actually want. Still: silence.
Common failure modes:
- Keyword matching - "ISO 27001" scores a point whether or not you actually applied it for six years.
- Title mismatch - "Lead Security Research Engineer" doesn't map cleanly to US-centric "Staff AppSec" templates.
- Location fiction - "remote" often means remote within three specific countries.
- Experience years theater - eight years required in a six-year-old framework.
I'm a security person. I recognize brittle systems. This one eats hope.
AI interviews
I've sat through AI screening rounds - recorded answers, timed chat prompts, logic puzzles adjacent to the role.
They measure camera comfort and fluency. They don't measure security judgment under ambiguity - asking clarifying questions, reasoning about trade-offs, knowing the difference between OWASP memorization and shipped fixes.
The worst part is hiring limbo: performing for a model that doesn't explain decisions, hoping a human later agrees you sounded "energetic."
Fake offers
Job searching publicly attracts scams. Transition is vulnerability.
I've seen fake companies, too-good offers with too little diligence, off-platform pressure, bank detail requests before contracts.
I'm a security engineer - I catch most of it early. The noise still consumes attention I need for real opportunities.
Rejections stack
Ghosting. Template nos. "Strong profile, but we need more hands-on X." Late-stage compensation mismatches.
Each rejection is logically fine. Psychologically, they accumulate.
I'm not fragile. I'm tired of explaining a decade of work to people who can't see past a malformed regex.
What actually helps
- Warm intros - still the highest signal.
- Writing in public - filters for humans who speak your language.
- Targeted applications - ten thoughtful beats fifty cloned.
- Building Mirror in parallel - demonstrates I ship, not just audit.
Where I am
Still open to security engineering and secure development leadership - roles where threat modeling and code aren't different religions.
Still getting rejected. Still applying.
If you're in the same loop: the infrastructure is hostile by neglect. The problem isn't only you.
Don't confuse market volume with personal failure.